ECONOMY

Data leak from ministry's 'Everyone's Startup' platform traced to partner firm, not outside hacker

by
Shin Hea-won
Published : June 21, 2026 - 18:48:40
    • Copy Completed!

View Korean Original

Firm obtained private data through abnormal API calls; ministry's public statement omitted key details already disclosed to privacy regulator

Han Sung-sook, minister of SMEs and Startups and nominee for prime minister, delivers remarks at the launch ceremony for the first cohort of the "Everyone's Startup" program at SVC Seoul in Mapo-gu on June 16. [Yonhap]
Han Sung-sook, minister of SMEs and Startups and nominee for prime minister, delivers remarks at the launch ceremony for the first cohort of the "Everyone's Startup" program at SVC Seoul in Mapo-gu on June 16. [Yonhap]

A data breach that exposed the personal information and startup ideas of thousands of applicants to the Ministry of SMEs and Startups' "Everyone's Startup" platform was not the work of an outside hacker — it was carried out by a partner company participating in the project, it has emerged.

According to a personal data breach report that the Korea Startup Promotion Agency submitted to People Power Party lawmaker Kang Seung-gyu of the National Assembly's Trade, Industry, Energy, SMEs and Startups Committee on Sunday, the agency said the incident began at 9 a.m. on June 15, when an AI solutions firm involved in the project "obtained undisclosed email addresses through abnormal application programming interface (API) calls and sent promotional emails to those addresses." The firm is believed to have used specific API calls and AI-powered web crawling — automated data collection — to access inadequately secured server data, including participant profiles and evaluation comments that were hidden from the on-screen display.

Unlike a typical attack by an outside hacking group, this incident is expected to generate significant fallout because the perpetrator was a company working as an internal partner. The AI solutions firm had been tasked with helping participants refine their startup ideas. The leaked data includes private email addresses, evaluation comments and idea summaries. The Korea Startup Promotion Agency notified all 5,000 selected participants by text message and has filed reports with the Personal Information Protection Commission and other relevant authorities. The full scale of the leak is still being determined.

Questions have also been raised about whether the ministry tried to downplay or conceal the incident. When news of the breach broke on June 18, the ministry issued a press release at 1:30 p.m. stating only that "user complaints were received about promotional emails sent to private email addresses," without disclosing that the solutions firm responsible for sending those emails was also the source of the breach. Yet the ministry had already filed a report with the Personal Information Protection Commission at 1:19 p.m. that same day — about 10 minutes earlier — in which it clearly described how the breach occurred. Suspicions of a premeditated act are also growing, given that the breach took place at 9 a.m. on June 15, immediately after the profiles of the 5,000 selected participants were made public, suggesting the partner firm may have known the schedule in advance.

In light of the seriousness of the matter, the ministry plans to hold a briefing Monday, chaired by First Vice Minister Noh Yong-seok, on the current status of the "Everyone's Startup" program and its future direction.

"There is a possibility that the data breach was caused by a company included in the AI solutions supply pool for the 'Everyone's Startup' program," Kang said. "Rather than pushing ahead recklessly with a project that did not even exist when the National Assembly reviewed the budget, the ministry should conduct a thorough review of its lax project management systems across the board."


hwshin@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ